All posts
All posts

August 24, 2026
All posts
Prior Authorization
Policy
Provider
August 24, 2026
CMS-0057-F requires Medicare Advantage, Medicaid, CHIP, and Qualified Health Plan payers to implement FHIR-based prior authorization APIs by January 1, 2027. Health systems don't have a direct compliance obligation under the rule itself, but the organizations that treat this window as a passive wait-and-see period are going to fall behind the ones actively preparing their payer relationships, EHR readiness, and MIPS attestation strategy right now.
This checklist breaks down what that preparation actually looks like, organized around the questions revenue cycle, patient access, and IT leaders are asking as the deadline approaches.
CMS-0057-F, the CMS Interoperability and Prior Authorization Final Rule, is a federal regulation that requires impacted payers to build standardized, FHIR-based APIs for prior authorization submission, tracking, and decisioning. Operational requirements, including 72-hour urgent and 7-day standard decision timeframes and specific denial reasoning, took effect January 1, 2026. The remaining piece, full API implementation across Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization APIs, is due January 1, 2027.
For a deeper breakdown of how this rule fits into the broader prior authorization regulatory landscape, see our Regulation & Compliance guide.
The rule's compliance obligation sits with payers, not health systems, but the operational impact doesn't stop there. Once payers stand up FHIR APIs, the health systems positioned to actually use that connectivity, rather than continuing to submit and track authorizations the way they did historically, are the ones who convert this regulatory shift into faster turnaround, fewer denials, and less manual staff time.
There's a compliance-adjacent incentive layered on top of that operational case, too. CMS has tied a new MIPS Promoting Interoperability measure to Prior Authorization API use, originally set as mandatory beginning with the 2027 performance year. A pending CY 2027 Physician Fee Schedule proposal would push that mandatory status to 2028, but that change isn't finalized, so the infrastructure work either way lands on the same timeline. The ones who aren't ready simply keep working the old way alongside a payer infrastructure that's evolved past them. That gap is the real planning problem, and it's solvable well ahead of the deadline.
Not every payer will be equally ready by January 1, 2027, and connectivity will roll out unevenly across national, regional, and delegated entities. Start by mapping which of your health plans are subject to CMS-0057-F, and which are likely to be early movers on API availability versus later adopters.
Prior authorization technology sits at the intersection of IT, revenue cycle, patient access, and compliance. Before technical implementation starts, confirm who owns this internally and whether a formal planning process, including a stakeholder list and a defined scope, is already underway.
Not all payer APIs will support the same lines of business, services, or submission capabilities at launch. Ask your vendor how they're validating and prioritizing payer connections, and whether your existing submission workflows (278 transactions, portal, eFax) will continue functioning as a fallback while API coverage expands.
Beginning with the 2027 performance year, eligible providers must annually attest under MIPS Promoting Interoperability that they used electronic prior authorization via a qualifying Prior Authorization API during the reporting period, or qualify for an exclusion. Decide now whether attestation will happen at the health system or individual physician level, since that decision affects how data needs to be tracked and reported internally.
FHIR-native architecture and Da Vinci implementation guide support are either foundational to how a solution was built or they're not. A vendor managing payer-side API connectivity on your behalf, while your existing EHR workflows continue functioning without disruption, removes the burden of building and maintaining individual FHIR connections payer by payer.
Does CMS-0057-F require health systems to build anything? No. The compliance obligation under CMS-0057-F sits with impacted payers, who must build the required FHIR APIs. Health systems don't have a direct build requirement, but they do need a strategy for connecting to and using that new payer infrastructure as it comes online, ideally through a prior authorization vendor that manages the API connectivity layer.
What's the difference between CMS-0057-F and MIPS electronic prior authorization requirements? CMS-0057-F is the interoperability rule that requires payers to build FHIR-based APIs. MIPS Promoting Interoperability is a separate CMS incentive program under which eligible providers must attest, beginning with the 2027 performance year, that they used electronic prior authorization through a qualifying API. The two are connected but distinct: one is a payer build requirement, the other is a provider reporting requirement.
When is the CMS-0057-F API deadline? Impacted payers must have Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization APIs operational by January 1, 2027. Operational requirements around decision timeframes and denial specificity took effect earlier, on January 1, 2026.
What happens if a health system isn't ready when payer APIs go live? There's no direct penalty for health systems under CMS-0057-F itself. The cost is operational rather than regulatory: organizations without a plan for using the new API infrastructure continue relying on slower, more manual submission and tracking methods while their payers' capabilities move forward without them, and they risk missing the readiness needed for 2027 MIPS attestation.
CMS-0057-F puts the build requirement on payers, but the advantage goes to the health systems that show up ready. Mapping your payer landscape, aligning internal stakeholders, working through EHR-specific readiness steps, and settling your MIPS attestation approach now, rather than in Q4 2026, is what separates organizations that experience this transition smoothly from those that scramble to catch up.
For help preparing your workflow for regulatory changes, contact us.

Allegheny Health Network Partnered with Humata to Centralize & Automate 200,000+ Annual Prior Authorizations
Prior Authorization
Provider
Technology

Cost Savings with Intelligent Prior Authorization Analytics
Provider
Prior Authorization
Technology

A Health System's Checklist for WISeR Readiness
Prior Authorization
Technology
Policy